Re: iptables anti-nimda anyone?

From: Rob 'Feztaa' Park (fezziker@home.com)
Date: 09/21/01


Date: Thu, 20 Sep 2001 23:32:11 -0600 (MDT)
From: Rob 'Feztaa' Park <fezziker@home.com>
To: Bugtraq - Focus Linux <focus-linux@securityfocus.com>
Subject: Re: iptables anti-nimda anyone?
Message-ID: <Pine.LNX.4.33L2.0109202331040.5968-100000@feztron.ath.cx>

On Wed, 19 Sep 2001, Konrad Michels (dis)graced my inbox with this:

> Hi everyone
> I don't suppose one of our iptables gurus out there has an iptables rule
> to filter out this damn nimda thing? I'm really annoyed about it
> filling up my apache logz and would love to drop the packets 'ere they
> get to the apache server . . .

I don't think that's possible, you'd have to be able to check the contents
of the actual packet; right now iptables is only capable of checking the
headers.

But believe me, i'd love to set up a rule that automatically drops nimda
traffic :)

-- 
Rob 'Feztaa' Park
fezziker@home.com
ICQ#: 49781692
:wq!



Relevant Pages

  • X & Gnome crashes the system with iptables
    ... kernel 2.4.21, ... I spent a lot of time to write rules for iptables to obtain a good firewall. ... # Support for connection tracking ... packets are denied until ...
    (comp.os.linux.x)
  • X & Gnome crashes the system with iptables
    ... kernel 2.4.21, ... I spent a lot of time to write rules for iptables to obtain a good firewall. ... # Support for connection tracking ... packets are denied until ...
    (comp.os.linux.setup)
  • X & Gnome crashes the system with iptables
    ... kernel 2.4.21, ... I spent a lot of time to write rules for iptables to obtain a good firewall. ... # Support for connection tracking ... packets are denied until ...
    (alt.linux)
  • X & Gnome crashes the system with iptables
    ... kernel 2.4.21, ... I spent a lot of time to write rules for iptables to obtain a good firewall. ... # Support for connection tracking ... packets are denied until ...
    (comp.os.linux.security)
  • PPPOE xDSL Firewall with IPTABLES
    ... don't know how to modify my firewall to account for this. ... Starts and stops the IPTABLES packet filter \ ... # Kill malformed XMAS packets ... # server/client to server query or response ...
    (comp.os.linux.networking)